fix: load config.yaml on boot; issue real device token; live smoke test

- main() previously used Config() defaults, silently ignoring config.yaml
  (port + token); now loads config.yaml from repo root (BRIDGE_CONFIG override)
- config.yaml: port 8766 (8765 taken on this host), real sha256 token for xiaozhi-main
- smoke_live.py: live WS verification (health, auth rejection x2, handshake, full turn)
- README: correct run command (python -m app.main)
- HANDOFF/plan: Phase 1.5 live-verified evidence
This commit is contained in:
2026-10-03 12:12:29 +07:00
parent 52d9ecfb70
commit b00312cbe5
6 changed files with 134 additions and 6 deletions

View File

@@ -23,8 +23,14 @@
```bash
.venv/bin/python -m pytest -q # → 18 passed
.venv/bin/python -c "import app.main" # → OK
.venv/bin/python -m app.main # → serves /health + /ws/xiaozhi on config.yaml host:port
.venv/bin/python smoke_live.py # → live WS smoke: health, bad-token/bad-device rejection,
# handshake, spoken turn (stt→state→text→audio) — PASS
```
CON-002 checked: no torch/typhoon/whisper/jait/opus/numpy in `sys.modules` after import.
Bug found+fixed on this host: `main()` ignored `config.yaml` (used `Config()` defaults —
wrong port + zero-hashes token); now loads config.yaml from the repo root
(override with `BRIDGE_CONFIG`). Real device token issued for `xiaozhi-main`.
## Do this first on the voice-server (ordered)
@@ -36,7 +42,13 @@ CON-002 checked: no torch/typhoon/whisper/jait/opus/numpy in `sys.modules` after
4. **TTS**: `tts.engine: jaitts` — point `jaitts_endpoint` at JaiTTS on the 5060 Ti. First-audio latency is the headline metric.
5. **Hermes transport**: `hermes.transport: openai_http` + `base_url`/`api_key` for the Qwen 3.8 vLLM endpoint (V100). Streaming SSE path already implemented in `app/hermes/__init__.py`.
6. **Device auth**: generate a real token per device, `token_hash: sha256(token)` hex in `config.yaml`.
7. **Bind**: keep `host: 127.0.0.1` — the Cloudflare tunnel is the only external surface (REQ-012). Add the tunnel hostname → `127.0.0.1:8765` on the existing tunnel.
- Done on this host (2026-10-03): `xiaozhi-main` token = `8a07643d106f9282a8f2eb1161da4f73657ce99b6602b98df89d011b8caf48a2`
(store in the ESP32 firmware config; `token_hash` in config.yaml is its SHA-256).
- ⚠️ config.yaml is committed to the repo — this token is public. Rotate it (new token,
new hash) before the device leaves the lab, or move config to a gitignored overlay.
7. **Bind**: keep `host: 127.0.0.1` — the Cloudflare tunnel is the only external surface (REQ-012).
Point the tunnel hostname at `127.0.0.1:<port>` where `<port>` is the value in `config.yaml`
(this host uses 8766 — 8765 is taken by another local service).
## Known sharp edges